Vulnerability

XSS Vulnerabilities in Azure Services Let Attackers Execute Malicious Scripts

Two severe vulnerabilities in Azure services, Azure Bastion and Azure Container Registry—that allow Cross-Site Scripting (XSS) by leveraging a flaw in the postMessage iframe have been discovered.

Cross-site scripting (XSS) is malicious scripts being unintentionally executed by users’ browsers after being injected by a threat actor into a reliable website.

Threat actors may acquire unauthorized access, compromise network systems, or even steal data when that happens.

Orca Security notified the Microsoft Security Response Centre (MSRC) to fix and validate the vulnerabilities; MSRC could reproduce the problems after being made aware of them.

According to reports, both vulnerabilities have been validated and addressed, necessitating no more action from Azure customers.

XSS Attack Flow With Embedded postMessage IFrames

Applications communicate messages from one window to another using postMessages. PostMessages have many security implications, too, and if they’re not done properly, they might constitute a significant security risk.

“The postMessage iframe vulnerability that we discovered in Azure Bastion and the Azure Container Registry allowed attackers to embed endpoints within remote servers using the iframe tag,” researchers said.

The cyber security team learned that by using this flaw in conjunction with improper postMessage origin validation, attackers might have possibly compromised sensitive data by executing malicious javascript code.

Additionally, a threat actor would need to undertake reconnaissance on several Azure services to identify vulnerable endpoints embedded inside the Azure portal that could be missing X-Frame-Options headers or have poor Content Security Policies (CSPs).

Azure XSS Attack Flow

The adversary might then create the necessary payloads by embedding the weak iframe in an actor-controlled server (like ngrok) and developing a postMessage handler that sends the malicious payload after analyzing the valid postMessages delivered to the iframe from portal.azure[.]com.

“As the victim accesses the page, the malicious postMessage payload is delivered to the embedded iframe, triggering the XSS vulnerability and executing the attacker’s code within the victim’s context,” researchers said.

Major consequences may result from this, such as unauthorized access to data, loss of administrative rights, data theft, unauthorized modifications, or interruption of Azure services.

The Azure Bastion Topology View SVG exporter or the Azure Container Registry Quick Start were found to be vulnerable to manipulation by a specifically constructed postMessage in a proof-of-concept (PoC) presented by Orca. This allowed the payload of an XSS to be executed.

Looking For an All-in-One Multi-OS Patch Management Platform – 

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago